Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2674▼ 561 respecto a la semana anterior
Críticas / altas1270▼ 252 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)217▼ 222 respecto a la semana anterior
23.894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.26% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Crítica (9.9) | 0.43% | — | Oracle Peoplesoft In-memory Project Discovery | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft In-Memory Project Discovery product of Oracle PeopleSoft (component: Project Discovery). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft In-Memory Project Discovery.… | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 12/8/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.34% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Project Portfolio Analysis | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Portfolio Analysis product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Portfolio… | |
| Analizada | Baja (3.1) | 0.25% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Project Intelligence | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Project Intelligence product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Intelligence.… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Project Contracts | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Contracts. Successful… | |
| Analizada | Alta (7.8) | 0.18% | — | Oracle Peoplesoft Enterprise FIN Project Costing | 21/7/2026 | 6/8/2026 | Vulnerability in the PeopleSoft Enterprise FIN Project Costing product of Oracle PeopleSoft (component: Projects). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where PeopleSoft Enterprise FIN Project Costing executes to… | |
| Analizada | Baja (3.1) | 0.25% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Manufacturing. Successful… | |
| Analizada | Baja (3.6) | 0.11% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Analizada | Media (4.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Analizada | Media (5.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| En análisis | Media (5.7) | 0.14% | — | Oracle Project Manufacturing | 21/7/2026 | 31/7/2026 | Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center). The supported version that is affected is V16. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Project Manufacturing executes to… | |
| Analizada | Alta (7.6) | 0.16% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | The Classic (BR/EDR) L2CAP signaling handlers l2cap_br_conf_req() and l2cap_br_conf_rsp() in subsys/bluetooth/host/classic/l2cap_br.c validated the minimum command size against buf->len (the bytes remaining in the whole received PDU) instead of len (the per-command data length from the L2CAP signaling header). Because… | |
| Analizada | Media (5.5) | 0.14% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | The DesignWare SPI driver (drivers/spi/spi_dw.c) computed the SPI BAUDR clock divider as info->clock_frequency / config->frequency without validating config->frequency. spi_transceive is a Zephyr __syscall and its verify handler (drivers/spi/spi_handlers.c) copies the caller-supplied spi_config from userspace without… | |
| Analizada | Alta (8.1) | 0.39% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | The MCTP-over-I2C+GPIO target binding in Zephyr (subsys/pmci/mctp/mctp_i2c_gpio_target.c) processes pseudo-register writes from an I2C bus master byte-by-byte in mctp_i2c_gpio_target_write_received() without validating the order or the receive buffer. In the affected versions the MCTP_I2C_GPIO_RX_MSG_ADDR (data)… | |
| Analizada | Media (6.5) | 0.14% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | The CONFIG_USERSPACE syscall verifier z_vrfy_k_poll() in kernel/poll.c allocates a kernel-side copy of the user-supplied k_poll_event[] via z_thread_malloc() and then validates each event's object handle. Before this fix, validation used K_OOPS(K_SYSCALL_OBJ(...)) inline inside the loop, which kills the calling thread… | |
| Analizada | Media (6.5) | 0.39% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the provisioning protocol watchdog timer unconditionally at the top of the function, before the FCS check and before the ADV_LINK_INVALID check. Once a provisioning attempt fails, prov_failed() sets… | |
| Analizada | Media (5.5) | 0.14% | — | Zephyrproject Zephyr | 21/7/2026 | 30/7/2026 | The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when CONFIG_UART_USE_RUNTIME_CONFIGURE is enabled, called LPUART_Deinit() at the start of mcux_lpuart_configure(), which disables the LPUART peripheral clocks. The requested configuration is validated only afterwards (in mcux_lpuart_configure_basic),… | |
| Analizada | Media (5.2) | 0.27% | — | Fogproject | 21/7/2026 | 7/8/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `buildRow()` method in `fogpage.class.php` substitutes data values into HTML table cell templates using `str_replace()` without any HTML escaping. An unauthenticated attacker who… | |
| Analizada | Alta (8.2) | 0.27% | — | Fogproject | 21/7/2026 | 7/8/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This… | |
| Analizada | Alta (8.7) | 0.41% | — | Fogproject | 21/7/2026 | 7/8/2026 | FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `selectForm()` helper in `fogpage.class.php` renders `<option>` labels using raw, unescaped user input. An unauthenticated attacker who knows any registered host's MAC address can… |